VDB

ICSA-25-135-04

ICSA-25-135-04 PUBLISHED CVSS 7.5 HIGH

Desigo CC deployments that use Installed Client are impacted by an information disclosure vulnerability which could result in information leak from the Desigo CC server. The other Desigo CC client options, Windows App Client and Flex Client, are not affected by this vulnerability. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Desigo CC

Timeline

  • May 13, 2025 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›